deeptools

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is designed to assist in running NGS data analysis commands. It includes a helper script, scripts/workflow_generator.py, which generates bash scripts containing deepTools commands. The script uses shlex.quote for all interpolated variables and a strict regex filter (SAFE_PATH_PATTERN) for file paths, which effectively mitigates command injection risks from user-supplied inputs.
  • [DYNAMIC_EXECUTION]: The workflow_generator.py script performs dynamic generation of bash script files. This implementation is safe as it uses pre-defined templates and applies comprehensive sanitization and validation (via sanitize_path, sanitize_path_list, and sanitize_positive_int) to all inputs before script creation.
  • [SAFE]: All identified dependencies, such as deepTools, are standard, well-known bioinformatics packages. The skill provides legitimate utility for life sciences research without any evidence of prompt injection, unauthorized data access, or persistence mechanisms.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — deeptools